Woah…
I sadly have to admit that the part about the crypto of andOTP being pretty bad is true. This is partially due to the fact that I had absolutely no clue about cryptography and very little coding experience when I forked it.
Says the andOTP developer… that app which is praised to high heavens on so many security and privacy forums…
That proves a point I’ve been making here and there : 2FA by app is not a mature technology.
Security is hard to get right. Having a developer of a cryptographic application candidly admitting he had no clue about cryptography (or coding !), when he first “developed” it…
It also proves something else : plenty of people will say a program is terrific, and the one to use for privacy, just because it’s open source. At that point, “open source” is just a synonym for “abides by our religion”, “belongs to our sect, therefore nice”, etc.
